The Regulation notes that controllers and processors “should evaluate the risks inherent in the processing and implement measures to mitigate those risks”115. This same consideration is mentioned several times throughout the Regulation, requiring the controller and the processor to take risks into account at many stages throughout the lifecycle of the personal data in question. While it stops short of saying that the organisation should have an explicit risk management programme, it is clear that a systematic and comprehensive approach is the best way to ensure compliance.

Risk management is now a standard expectation of corporate management and, while smaller organisations might manage risk relatively informally, ...

Get EU General Data Protection Regulation (GDPR): An Implementation and Compliance Guide now with the O’Reilly learning platform.

O’Reilly members experience live online training, plus books, videos, and digital content from nearly 200 publishers.